Skip to content

Key AI Governance Considerations for State and Local Government

Posted by Betsy Hedrick , Michael Garber and Antonina McAvoy in Business Advisory, State and Local Government, Risk Advisory, Artificial Intelligence.

Key topics covered in this article:

  • AI governance is becoming a critical priority for state and local governments as employees use AI tools directly and vendors embed AI into existing platforms. The biggest risks often involve sensitive data, unreliable AI-generated outputs, public records obligations, and limited visibility into how third-party vendors are using AI.
  • A practical governance approach starts with understanding where AI is already in use, assigning ownership, updating existing policies, and defining acceptable use guidelines. Governments also need employee training, stronger vendor conversations, and added documentation for higher-risk use cases that could affect the public.
  • Early examples from states like Massachusetts, North Carolina, and Oklahoma show that AI governance can be built into real operations without starting from scratch. The goal is not to eliminate AI, but to manage it responsibly in a way that supports accountability, risk management, and public trust.

 

Key AI Governance Considerations for State and Local Government

Artificial intelligence is already part of many state and local government operations. Employees may be using dedicated AI tools to summarize documents, draft communications, or analyze information, and AI capabilities are increasingly built into software organizations already use. At the same time, many organizations are still working to update existing policies to account for AI. Leaders now need to understand how AI is being used across their organization and what controls should surround that use, particularly when it involves public data or records. Informed governance helps organizations manage that risk while still realizing the benefits AI offers.

Where Governments Are Seeing the Greatest Risks

Many AI risks do not come from intentional misuse. They come from employees using available technology to do their jobs more efficiently without clear guidance about the risks that may come with it. For state and local governments, three areas deserve particular attention: data and AI-generated outputs, public records and retention, and third-party vendors.

Data and AI-Generated Outputs

Government employees work with many types of information that may not be appropriate to share with every AI system, such as resident data, financial records, or other sensitive information. That makes it important to understand what data can be entered and how the AI provider handles it. For example, state and local leaders should know if the information is retained or used to train AI models.

On the other side, AI-generated information needs appropriate human review. AI can produce inaccurate or incomplete information even when it sounds convincing. A qualified employee should evaluate outputs before they are acted on, shared externally, or used to inform a community decision. The level of review should reflect how the information will be used. Drafting an internal email presents a different risk than using AI-generated information to inform a decision or process that affects the public. A tiered system can help distinguish between lower-risk uses that may require basic review and higher-impact uses, such as eligibility, enforcement, or financial reporting, that require stronger oversight and documentation.

Public Records and Retention

AI opens up new territory when it comes to public records. Prompts, outputs, transcripts, and chatbot interactions may qualify as government records depending on applicable law. If AI helps draft an official communication, summarizes a meeting, or communicates with a resident, for example, what needs to be retained? Can the system preserve and retrieve that information when necessary? Answering these questions early and making sure the technology supports proper retention and retrieval can put governments in a much better position than trying to sort it out after the fact.

Third-Party Vendors

AI can enter government operations through vendors even when an organization has never intentionally purchased an AI product. ERP systems, financial systems, and other applications are adding AI capabilities too. That makes AI a vendor management issue. Governments need to understand how vendors use AI, what government data their systems can access, what happens to that data, and what controls are in place to protect it.

Contracts and vendor agreements should also address sub-processor access, incident notification obligations, and whether the government retains the ability to evaluate or restrict new AI features before they go live. These questions can be built into existing procurement and vendor management processes. The conversation should continue after the contract is signed because vendors may add or change AI capabilities over time.

Building a Reasonable Approach to AI Governance

Reasonable AI governance does not mean starting from scratch or trying to anticipate every possible use of AI. State and local governments already have policies and controls covering technology, cybersecurity, privacy, records management, procurement, vendor management, ethics, and internal controls. The task is determining where AI changes the equation and where existing practices need to be updated, rather than creating a standalone program.

The NIST AI Risk Management Framework offers guidance on managing AI risk, and a recent GAO report addresses privacy considerations for government agencies. A practical roadmap includes:

Inventory AI use. Look across departments, existing systems, and vendor platforms to understand where AI is already being used.

Establish ownership. Decide who will coordinate AI governance and how responsibilities will be shared across departments.

Review existing policies. Identify where policies covering public records and internal controls need to be updated for AI.

Develop acceptable use guidelines. Define which tools and uses are approved, what information cannot be entered into AI systems, and when additional approval is required.

Begin vendor conversations. Ask about AI capabilities within the platforms and find out how AI interacts with data, records, and governance requirements.

Document higher-risk use cases. For AI uses with greater public impact, maintain a record of approvals and responsible owners to create an appropriate governance trail.

Train employees. Give staff practical guidance on approved tools, restricted information, appropriate uses, output validation, and records responsibilities.

Monitor and reassess. Revisit AI governance regularly as tools evolve, vendor capabilities change, and new use cases emerge across the organization.

The goal is not to eliminate AI. The goal is to understand it, manage it, and use it responsibly.

How States Are Leading the Way

Early adopters are taking different approaches to AI governance based on their priorities and needs. While it is too early to know how these approaches will perform over time, the examples below show how some states are beginning to put governance into practice.

Massachusetts became the first state to deploy a ChatGPT-powered AI assistant across an entire branch of government, giving 40,000 executive-branch employees a secure tool to work with. The platform operates in a walled-off environment that protects state data and prevents prompts from training public AI models. The rollout also includes governance considerations like privacy oversight, regularly updated AI policies, and optional employee training.

North Carolina is starting with data classification. The state is working to identify what data it has and how sensitive it is. That information can help agencies determine what data is appropriate to use with AI, what may need to be anonymized or otherwise handled differently, and what should remain restricted. The work is collaborative, bringing together privacy, AI policy, and cybersecurity leadership to build a comprehensive governance structure.

Oklahoma recently launched a shared enterprise AI platform that gives state agencies a common foundation for developing and deploying AI tools. The platform includes built-in governance, security, and data standards. Two tools are already in beta: one that helps review administrative rules for opportunities to simplify, and another that provides procurement guidance.

Moving Forward with AI

AI will continue to change, and governance will need to evolve with it. State and local governments do not need perfect governance before moving forward. By understanding how AI is being used and putting reasonable guardrails around that use, they can manage risk, maintain accountability, and create a stronger foundation for capitalizing on the opportunities.

For an AI governance assessment that inventories current AI use, evaluates governance and controls, identifies gaps and vendor-related risks, and provides a prioritized roadmap, contact PBMares State and Local Government Partners Betsy Hedrick and Michael Garber or Cybersecurity & Risk Advisory Services Partner Antonina McAvoy.


Be sure to consult with your financial or tax advisor on this topic as individual situations may vary. The information contained in this article or webinar, and any related materials, are for informational purposes only, and cannot be relied upon for legal, financial, tax, accounting, or other professional services advice. The content is provided on an “as is” basis and PBMares makes no representations or warranties about the accuracy or sustainability of any information for your purposes. For any specific questions you may have, please contact us.

This content is accurate at the time of publication. Always ensure you are reviewing the most recent information available. Contact your tax or financial advisor if you need clarification.

Contact Us

About the Authors

Antonina McAvoy
Antonina McAvoy

CISA, CISM, QSA, PCIP
Partner, Risk Advisory Services
Norfolk

Antonina McAvoy specializes in cybersecurity, data protection, and privacy. She has 14 years of experience leading and performing a wide spectrum of cybersecurity reviews.

View Bio
Betsy Hedrick
Betsy Hedrick

CPA
Partner, State and Local Government Team Co-Leader
Harrisonburg

Betsy specializes in audits of local governments and governmental entities, including counties, cities, towns, authorities, boards and commissions.

View Bio
Michael Garber
Michael Garber

CPA, MBA
Partner, State and Local Government Team Co-leader
Harrisonburg

Michael is experienced in planning, supervising and executing audit and accounting engagements.

View Bio

Get News, Alerts, and Guidance

PBMares provides timely insights that help businesses build smarter, well-informed strategies. Join them.